ITSec14 wrote: » Security must support the needs of the business.
dmoore44 wrote: » A few articles to take note of:https://techcrunch.com/2016/11/29/every-company-is-a-technology-company-but-most-dont-behave-like-one/https://www.forbes.com/sites/forbestechcouncil/2017/01/23/why-every-company-is-a-technology-company/#37a2b63257ae While I understand the point you're making - that security shouldn't be an impediment to the ultimate objective of the company (i.e. make money), the reality of the situation is that the vast majority of companies are now wholly dependent on technology, and that technology needs to be secured... which means that some areas of the business are going to be inconvenienced by security requirements... Why? So that vulnerabilities are patched in a timely manner, so that the network properly segmented, so that access to sensitive data is restricted, so that the least-privilege principle is followed, etc... All of these are basic block & tackle security controls, but organizations still struggle with them because they "don't meet the needs of the business"...